Building agent businesses. CEO & co-founder @Obol_Collective, @dv_labs. Previously @BlockdaemonHQ, @Consensys. Pronounced 'Ush-sheen'. šŸ‡µšŸ‡øšŸ‡±šŸ‡§šŸ‰

As Ethereum moves away from Proof of Work to Proof of Stake, we cannot take its decentralisation for granted. We need decentralisation in depth, and we at @ObolNetwork are enabling the next frontier of decentralised network validation. blog.obol.tech/tackling-the-…
26
44
260
What are some of the biggest single-private-key wallets that sign programmatically? MEV bots, Exchange hot wallets maybe, not oracles (multisig), not bridges (multisig), not defi, …. Anything with a decent chunk of value to protect matures to using multiple setups with fault tolerance and diversity for security. On the consensus layer, I think we’re lagging behind through complacency. I would say less than 1% of stake if not 0% are running on proper no single point of failure setups, depending on how militant you want to be about how you define it. I think we hand wave at the fact that a hacker can just destroy your money not steal it, so it’s not as compelling for them to go after, which may be true, but I’m not sure it’s enough; when the costs of AI-enabled spear phishing campaigns are decreasing and their quality increasing. Defence needs to be successful every single time, offence just has to succeed once. That’s not symmetrical. We had a near-miss with 10% of the validator set just last year we’ve mostly forgotten about. It’s also rational to accumulate stolen keys rather than coming forward once they’ve stolen some. A hacker’s leverage grows non-linearly with the more ETH they can slash. We don’t know how many keys are already silently stolen, but I don’t think it’s 0. Let’s try and fix this before not after a disaster. Let’s run more distributed validators, and reduce the amount of single points of failure in our staking setups, and make Ethereum more anti-fragile.
6
3
21
1,071
oisin.eth | Obol retweeted
Consolidation changes the operational question more than the economic one. One key ends up carrying what 64 used to. We wanted that running on something we'd already put through production. 20% of our stake in CMv2 will be operated with Obol DVs.
Replying to @dsrvlabs
@dsrvlabs is putting Lido Curated stake onto Obol Distributed Validators. CMv2 densifies balances behind each key. DSRV is running that stake on Obol DVs. VASP-licensed. Read the full blog post: blog.obol.org/dsrv-cmv2-obol…
5
13
1,109
How I think pq-only fork scoping would play out
2
1
7
629
Ethrex have built a stellar execution client over the last few years, that we've been super impressed with in prod. Right now almost all of the network runs on just two execution clients, leaving us in jeopardy of losing finality if one fails, or even experiencing an absolute worst-case mass slashing event if both fail. We urgently need to get to a place where no client runs >33% of stake. One of the best ways to do that is to punish centralisation failures. I think that's why EIP 7716 gets an S-tier ranking from the team. If we don't penalise centralisation, we're not going to end up with decentralisation, simple as that.
Following up on our execution EIP tier list, we wanted to share our combined execution and consensus rankings for Hegota. We've followed the same EF Protocol scoring system and tier definitions for both lists. We'd also like to make a special mention of the post-quantum-ready deposit contract proposal. It didn't make it onto the Hegota EIP selection list, but we think proposals like this one should be included in the fork to prepare validator deposits for future post-quantum credentials. We'll expand on our thoughts about Hegota and the reasoning behind our rankings in the blog post we're preparing.
5
4
37
1,968
"In premise, penalizing correlated failures pushes the network toward the diversity we all want, and if the math checks out the lift on the client side is small. We had initial hesitation but the methodology was recently fixed by Oisin at Obol. A client bug that takes a large cohort offline gets penalized extra while minority clients and well-architected operator with diversified infrastructure barely notices. With the updated, clear and data-backed statement of exactly what behavior this is meant to discourage we are interested in seeing this ship if there is time." Glad to see vote of confidence and the Lodestar team in favour of EIP 7716 in Hegota capacity-permitting šŸŽ‰
We are proud to announce our preferences for Hegota EIP inclusions. Please find our thoughts here: hackmd.io/@matthewkeil/HkcMq…
1
4
19
1,131
I’m grateful to see Nethermind are supportive of anti correlation penalties. 7716 will encourage the chain to be more resilient to failures, and ultimately less exposed to worst case mass slashing situations.
1
3
19
1,081
I would say I'm surprised, but really I'm just disappointed with the EF Protocol's continued presumption of decentralisation as a given. Let me be clear: FOCIL doesn't work if the attester set doesn't want it to. The protocol priorities post focuses on post-quantum as a goal, fine, and pays lip service to CROPS; "FOCIL is HegotĆ”'s consensus-layer centerpiece. Our appetite beyond it is close to zero unless an addition directly supports post-quantum readiness." The elephant in the room the EF continues to ignore is that the chain is centralising at a rapid pace, and there is a lack of interest in either acknowledging the problems, or prioritising fixing any of them. For example, correlation penalties (7716) they describe as: "Adds slashing-logic surface for validator correlation with no CROPS or PQ contribution. Not a priority in a fork, we are trying to keep the CL scope light." This is inaccurate to start, 7716 has no slashing logic, and its misguided at best to assert that it doesn't contribute to CROPS. 7716 is the best EIP on the table to improve client diversity and penalise centralisation. It's not a panacea, but its what we have, it should not be DFI'd. Spending a year on H-star to ship FOCIL without addressing the validator set's underlying issues risks the big few centralised staking entities saying 'actually nah' and refusing to attest to slots with ILs they don't like. This costs them no rewards, thinking we'll socially slash them for it is wishful thinking, and now Ethereum is compromised and you need permission to use the chain. Preventing this outcome is not a matter of one EIP on the margin, it needs a cultural shift within the EF to realise they don't have a divine right from God to a decentralised chain, and that they can't just focus on academic challenges like PQ while ignoring real challenges like the ongoing acceleration in chain centralisation. We need quarterly reporting on the state of the chain, to make it harder for people to keep their head in the sand as to the severity of the situation. We need at least one EIP per fork focused on improving the nakamoto, staking gini, or other aspect of the validator set, and we need pragmatic, action-oriented leadership who care about Ethereum being CROPS beyond just a purity test. (I'm hoping that's @pcaversaccio). There are some people in the EF that care about the chain being CROPS for real, but unless we the community are outspoken and steadfast in our demands, they won't be listened to. Please show them why we're supporters of Ethereum and not any another centralised chain, please advocate for decentralisation and CROPS in H-star and beyond. Thank you.
The Protocol Cluster has published two new posts: HegotĆ” EIP Opinion Post and Tier List evaluates and grades all 62 EIPs proposed for HegotĆ”, providing the cluster’s first unified tier list for a network upgrade Current and Emerging Priorities covers commitments and research arcs, anchored on a quantum-resistant Ethereum L1 by Dec. 2029 Offered as one input to HegotĆ” scoping, roughly 60 researchers, engineers, and individual domain experts across all 9 teams in the Protocol Cluster contributed to the HegotĆ” tier list, providing 397 tier grades before discussing contested items live. The plan, commitments, and shared set of cluster-wide priorities covered in the companion post provide the context behind the final tier grades. The Protocol cluster will host a Reddit AMA on r/ethereum on September 16 at 2pm UTC to talk through these priorities, the HegotĆ” tier list, and anything else on your mind. → Submit questions ahead of time here: pad.ethereum.org/form/#/2/fo… Read the articles here: → EF Protocol - Current and Emerging Priorities: blog.ethereum.org/2026/09/07… → EF Protocol - The HegotĆ” EIP Opinion Post and Tier List: blog.ethereum.org/2026/09/07…
8
11
60
9,329
The 7716 mischaracterisation was fixed, but they still want to DFI it for a lack of evidence (which I think means they should leave it as TBD based on their stated rubric and help with the analysis if you ask me). Paging @nero_eth as the author and researcher that has analysed prior versions of 7716 on mainnet. šŸ¦‡ ā€œEIP-7716 increases penalties for correlated missed attestations. The impact on the current and future staker landscape, how effectively it reduces centralization forces, and edge cases such as multi-client setups that pause together during client disagreement all need more research and community discussion first. EIP-7716 is a good idea, but not a high priority in a fork where we are keeping CL scope light.ā€
7
303
The amount of vulnerability reports we get has also followed a similar graph over the same time period, it’s been hard to deal with. Lots of duplicate won’t-fix type issues (yes you can read our public APIs, that’s what they are for) but many valid modest issues that we’ve addressed and paid out for. Almost all of Ethereum’s $100b of active stake has at least one single point of failure that could leak its keys and get it slashed. Bad OpSec, bad supply chains, high exposure to particular software, operating systems, CPUs, and more could lead delegators who trust solo setups to up to 100% loss of their principal. We’re going to help simplify and highlight these single points of failure in a new initiative aimed at improving Ethereum’s security and its stakers’ ETH safety. If successful, most organisations will move from single point of failure setups to staking systems without a single point of failure, such as multi-operator distributed validator setups. This will better secure their stakers’ funds and ensure Ethereum never goes offline.
Cyber is having a moment Across 21 major software companies, including Apple, AWS, Microsoft, and Google: - Reported critical vulnerabilities never cleared 100 per month in four years - Since spring they've jumped to over 600 per month Charts of the Week: a16z.news/p/chart-of-the-wee…
2
3
18
1,277
This is a massive breakthrough for post quantum blockchains. Threshold signatures are a fundamental building block for the secure use of a blockchain and until now, there was no solution for how to make them with a post quantum scheme. Ethereum will be post-quantum secure and it won’t have to give up application and consensus level security to achieve it. Post quantum distributed validators when?
Can a sufficiently powerful quantum computer forge the signatures used to authorize Bitcoin and Ethereum transactions? What would it take to upgrade both networks before that happens? In this new lecture, Stanford cryptographer @danboneh explores why blockchains may turn to signatures built from hash functions. He also presents new research on threshold signing. The talk ends with the questions Bitcoin still has to answer, including whether post-quantum signatures will require larger blocks, what happens to abandoned coins, and how someone such as Satoshi could prove ownership after Bitcoin’s current signatures have been retired. 00:00 Why blockchains need to prepare for quantum computers 03:05 Why Bitcoin may bet on hash-based signatures 06:25 The ā€œbig footgunā€ in stateful signatures 08:58 A quantum-safe signature that takes one billion hashes 14:13 Inside SLH-DSA’s virtual tree 20:30 How Bitcoin and Ethereum could make the switch 23:48 What happens when a wallet loses its state? 32:47 Can threshold signing survive the quantum transition? 36:39 How to hide lattice cryptography from the blockchain 38:49 Why threshold one-time signatures seem impossible 45:36 How context prevents forged signatures 49:37 The forgotten idea behind Winternitz signatures 54:50 Turning one-time signatures into threshold signatures 1:04:27 Will quantum-safe signatures require bigger Bitcoin blocks? 1:06:26 Abandoned bitcoin and Satoshi’s recovery problem
7
15
57
4,798
This inaugural CFTC innovation advisory committee meeting is amazing to listen to. Kudos to @MichaelSelig and team for the openness and approachability. Going on two hours of founders and leaders expressing their gratitude to the commission for the newfound approachability and willingness to regulate sensibly contrasted against their lived experience of persecution under previous admins. Super encouraging to hear and I look forward to seeing what comes from it.
1
15
857
oisin.eth | Obol retweeted
Pluto, the DVT client written in Rust and developed by @Nethermind, is in the final stretch of becoming production-ready. Thanks, @OisinKyne, @Obol_Collective, for working together on this!
Two clients. One cluster. Pluto and Charon are validating side by side on the Hoodi testnet. šŸ§µā¬‡ļø
3
24
980
Institutions care about risk management. Ensuring that their customers' funds are not at risk to any one single anticipated failure, nor to one software provider is a requirement for adoption. @BitcoinSuisse_ are one of the OG custodians and staking providers. They have over a decade of experience to prove that they understand risks in Ethereum, and what they mean for their customers, auditors, and regulators. They went all-in on Distributed Validators, and before long all other institutional staking offerings will too.
Awesome news! As one of the first institutional staking providers fully switching to Obol, having an alternative client eases many technology risk discussions with regulators and auditors... šŸ’Ŗ Can't wait to try it out!!
2
9
725
Two production distributed validator clients will introduce a whole new level of resilience and security for Ethereum Staking setups. If you do a distributed key generation with half Charon clients and half Pluto clients; not only will no operator see the full private key, there's not even one software implementation helping you create them that interacts with all of the private key shares. This idea of not having one single piece of software (or hardware or human) that can cause the compromise of a validator's private keys is where the ecosystem is maturing towards. I call this a stage 1 validator setup. Stage 2 is when a single point of failure doesn't even take the validator offline. Tens of billions of dollars in companies and funds are staking their investors' ETH for them. One developer getting phished or one software supply chain being compromised is not an acceptable risk for what could be a double digit % loss from the slashing penalty or worse, and operator failure is not necessarily covered in all staking insurance fine print. This is why institutions will stake their ETH with professional operators running collectively as part of a Stage 1+ distributed validator rather than individually. Two clients brings us another step closer to achieving that vision.
Two clients. One cluster. Pluto and Charon are validating side by side on the Hoodi testnet. šŸ§µā¬‡ļø
1
2
23
3,015
We're not recommending Pluto for mainnet just yet. We'll wait until its further polished and assessed for security before making that recommendation. (But I've been pleased with it on mainnet so far!)
2
224
I don’t think we should be sacrificing censorship resistance for the staking ratio CROPS > Ultrasound money
"We don't really have 100 billion dollars of security, we really have 5 million a day" EIP-8363 critic Oisin Kyne on the censorship risk he says the proposal underrates "The main reason I'm not happy with the current proposed curve is this idea of it going to zero. There's more than one metric that matters for Ethereum security. The one put up front is finality, we have this amount of ETH that will be guaranteed burned if a transaction ever becomes undone, and I agree the research says tens of billions of dollars getting destroyed is probably enough disincentive" "Where we diverge is that's not the only thing that can go wrong. We also have this risk where the people staking their ETH decide to be particular about what they include in a block, saying we're only going to attest to blocks that do what we want, that don't have people we don't like in them. If they do that there's no penalty, so long as there's 51% of them or more doing it, it costs them nothing" "The plan we have is, oh no, maybe we'll coordinate as a group and destroy all their ether for doing so, but I think that's a very big risk to hedge all of Ethereum security on. I don't think we should be sacrificing censorship resistance for the staking ratio" "The fancy word is the Nakamoto coefficient, which comes from Bitcoin, this idea of how few orgs make up 50% of hash power or stake weight. We don't really have 100 billion dollars of security, we really have 5 million a day at the current curve, and depending on where the equilibrium lands it might be a million dollars a day or less. I don't know if that's enough to protect a trillion dollar computer"
5
4
47
4,792
Catch me, @owocki, and @jdetychey on @laurashin's Unchained Pod to hash out Ethereum issuance in the coming minutes!
Six researchers proposed burning Ethereum's staking issuance to zero. Aave, Lido, Ether[.]fi and SharpLink lined up against it within 48 hours. @jdetychey co-wrote it. @OisinKyne runs a staking company that opposes it. @owocki wonders how the community builds consensus They all join me on the show today at 1pm ET DON'T MISS IT! Tune in šŸŽ§ nitter.net/i/broadcasts/1XxygwBaM…
1
1
24
2,475
There's a lot of bluster about sockpuppets and deleting comments in the issuance debate. Lets not lose sight of the actual outstanding questions about the proposal and ensure they get researched and addressed such that the community can have an informed debate about Ethereum's security. - None of the issuance analysis includes costs, when you do, this proposal is not good for solo stakers, it makes them worse off both nominally and relatively versus other types of stakers. - None of the issuance analysis accounts for the fact that ~97% of the network makes a real rate of return on the existing curve no matter the equilibrium because they are not staking only their own eth. This happens on both ends of the spectrum, the extremely large professionals, and the extremely small homestakers. Only the ~1% of solo stakers are focused on in the analysis so far (without their costs being accounted for which significantly alters the analysis). - No other large PoS chain has runaway staking. These chains all have far larger dilution, and far less penalties for PoS failures. It tracks that Ethereum's equilibrium on this curve is likely lower than them (so <60% imo). I am not aware of a reason why in Ethereum, delegators will take more risks, for less rewards, while there are also better alternative uses for their capital (including simply protecting it in a cold wallet for the lowest dilution in the ecosystem). - Ethereum does not have $100b in economic security, its likely under a million dollars per day. This proposal could drive it down 5-10x from there. There is no analysis as to whether this is likely enough of a security budget to protect Ethereum from a concerted attack. - We have no agreed upon tracking of the network's Nakamoto (nor gini), these are measures of how easy it is to take over the chain, or how disastrous a failure of a particular multi-sig, smart contract, or custody platform might be. We should first be tracking them, and secondly we should be consensus-seeking on what is a sufficient number for them. I believe a Nakamoto of 10 should be the minimum tolerable floor. (and that gini needs to go down not up as it has been) - Ethereum's security (Nakamoto) has been falling for ~2 years as the chain centralises. This isn't only due to the current curve, the delegation rate has been pushed far lower in this time, and the illiquidity penalty of native staking is forcing delegators to choose the most liquid staked eth offerings. We should be trying to improve the security posture of the chain rather than exacerbating the problems it faces by making the majority of delegation options non-viable. Correlated downtime penalties, a burn2exit feature, and boosted whistleblower rewards on key compromise, could all push the mean preference to solo stake or delegate stake to the long tail of operators, which would improve the chain's security (nakamoto) rather than hurting it. - Stake quality is more important for Ethereum's security than stake quantity. The amount of operators it takes to control the chain is what we should care about, not the viability of a finality reversion event. We should not be damaging the chain's security to push a ratio by likely less than 20%. - Without a cost model of stake, we haven't a good understanding of where equilibrium might be under the proposal (nor the existing curve). Backing into it from costs, I think 60m eth could be staked for as little as $5m per year by the biggest operators (0.002% issuance per year). If you account for MEV, non-ETH perks given to delegators to stake, and the value in controlling Ethereum, I think its very feasible for equilibrium under the new curve to be 45% or higher. An issuance that low would make all but the largest orgs non-viable. - Making Ethereum more centralised is more likely to re-value Ethereum in line with other centralised chains than it is to be rewarded with an increased valuation. Ethereum's value comes from its credible neutrality and its decentralisation. Changing issuance in the proposed manner hurts both. - We are a couple hard forks away from Real Time Proving, and a switch to Post Quantum Ethereum. The cost model for this chain is vastly different than the one we have today. Proposing blocks will take a server rack worth of expensive GPUs, and attesting with a Post Quantum signature scheme is also more costly than the existing scheme. We should be forward looking in this regard, and make sure we're making a change that allows block building to be at least modestly decentralised. Taking issuance to near zero and not making any allocation to the costs of proposing will lead to a world where as few as two entities can afford to eat the costs of producing blocks on Ethereum. We should not be re-doing the issuance model every couple years. Lets plan for the moment validation changes markedly, and lets build consensus for a change that best suits that future architecture. Forcing through a fast tracked change for a risk of dubious downside and dubious probability is not good for the network's reputation. - Cutting the security budget and losing a large amount of the operator set makes Ethereum less CROPS. Ethereum's scaling roadmap depends on having large amounts of independent operators on the network, to ensure its Data Layer remains available, and to ensure fork choice is not compromised. We have to decide should Ethereum's roadmap take decisions that favour its CROPS nature, or one that favours ETH's disinflation. I don't believe we should jeopardise the former for the latter. A maximum of 1.5% dilution is lower than almost every asset in the world, it is not so high as to cause CROPS issues imo, sub 0.3% is a bigger concern. These are not all of the concerns raised about this proposal, and some of these have been more addressed than others by proponents. The impact on DeFi and the Ethereum economy is also notable. I'm just flagging 10+ issues that are getting drowned out by infighting over the legitimacy of how we moderate this contentious debate. Lets focus on facts over feelings, and make a concerted effort to gather first-hand data and develop believable models, so that we can make informed decisions around what we think 'enough security' might look like for the chain on a multi-decade horizon. Thank you.
7
19
63
6,270
If you want to learn more about things i reference here, here are some of them: Costs to stake: validatorcosts.kyne.eu What is eth's real security budget: ethereum-magicians.org/t/eip… What types of data should we be collecting, and where is the tradeoff between validating on a smart watch versus pumping the gas?: nitter.net/OisinKyne/status/18687… How Ethereum will fail by attesters being selective about what they attest to, rather than a finality reversion event: web.archive.org/web/20220603… Ethereum's increasing gini: nitter.net/robplust/status/197587… Correlated downtime penalties (EIP-7716): ethresear.ch/t/supporting-de… Probably some more around too but that can be a start, reply if you've more questions.
Doesn't look too good already even without the withdrawal address bucketing. From 0.91 this time last year -> steadily increasing to 0.94 today. (data from @ratedw3b )
1
7
356
My math using the cost calculator which indicates a solo staker is worse off under the proposal than the existing curve
Solo staker's taxes are a supposed reason for capping issuance. Proponents argue that solo stakers would be better off under the cap than a high staking ratio where their rewards come with higher dilution. I think this argument falls apart when you model how much it costs to solo stake, which is unfortunately a lot. Electricity, hardware, internet, downtime, and the headaches of DIY are not free. At a 70% staking ratio on today's curve (higher than I believe we can reach for the sake of argument). A 32 eth solo staker makes ~1.9% APR, ~$1167 gross. Operating costs are $537 (calculator here: validatorcosts.kyne.eu/), taxes @30% are $350. You make $280 per year net. (0.46% APR). At a 40% ratio under a cap (lower than I believe we will reach for the sake of argument). You make ~0.8% APR, ~$491.50 gross. Operating costs are still $537, taxes are $147.50. You net to a $-193 loss. (-0.31% APR) This effect applies even if you pump your eth stake way up to minimise the fixed operating costs. You have to argue about eth dilution and what that might do to the eth price because of stock to flow models, or make generous assumptions about why delegators making 0.72% APR for no effort will unstake, to try and make the math make sense. What am I missing? P.S. You make $1050 (1.71% APR) and $442 (0.72% APR) under these options if you delegate instead of solo staking. We definitely need to solve the disparity in taxation, and to make solo staking more economical, but this EIP does not seem to be beneficial for solo stakers as it claims to be.
4
191